Loading...
Loading...
Atlassian Crowd 2.5.x before 2.5.4, 2.6.x before 2.6.3, 2.3.8, and 2.4.9 allows remote attackers to read arbitrary files and send HTTP requests to intranet servers via a request to (1) /services/2 or (2) services/latest with a DTD containing an XML external entity declaration in conjunction with an entity reference.
July 1, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-3925
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.